Your key includes a pair of keys. The public key which is included in the APK and the private key. The APK also includes the signature (the files are in the META-INF folder).
You must have both the public and the private keys in order to create the signature. You can verify the signature with the public key.
It should be very difficult to find the private key.